Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Do you patch servers that do not access the internet ?

Reply
Thread Tools Display Modes

Do you patch servers that do not access the internet ?

 
 
Bob
Guest
Posts: n/a

 
      03-10-2009

Hello all,

For years I have been a robot and patching all systems - desktops and
servers as MS releases them. I do test them first, then install via WSUS.

I have been thinking more ---- I have quite a few servers that do not access
the internet --- there are patches for the OS - Server 2000/2003, IE6/7, yet
I'm questioning myself ---- why patch the server OS and IE on those servers
if they don't access the internet. I would say definately all of my LAN
desktops, and just the servers that access the internet --- Exchange, FTP,
web server, the other servers, don't patch. All systems on the LAN do have
antivirus/spyware installed, my Exchange server also have Mail security for
SMTP installed.

So ---- what are your feelings/what do you practice ---- just patch servers
that access the internet ?

Thanks,
Bob

 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-10-2009
Hello Bob,

Definitely YES. All Virus etc. can also come with USB stick, disks etc.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello all,
>
> For years I have been a robot and patching all systems - desktops and
> servers as MS releases them. I do test them first, then install via
> WSUS.
>
> I have been thinking more ---- I have quite a few servers that do not
> access the internet --- there are patches for the OS - Server
> 2000/2003, IE6/7, yet I'm questioning myself ---- why patch the server
> OS and IE on those servers if they don't access the internet. I would
> say definately all of my LAN desktops, and just the servers that
> access the internet --- Exchange, FTP, web server, the other servers,
> don't patch. All systems on the LAN do have antivirus/spyware
> installed, my Exchange server also have Mail security for SMTP
> installed.
>
> So ---- what are your feelings/what do you practice ---- just patch
> servers that access the internet ?
>
> Thanks,
> Bob



 
Reply With Quote
 
Al Dunbar
Guest
Posts: n/a

 
      03-10-2009

"moncho" <> wrote in message
news:j0wtl.14505$...
> Bob wrote:
>> Hello all,
>>
>> For years I have been a robot and patching all systems - desktops and
>> servers as MS releases them. I do test them first, then install via WSUS.
>>
>> I have been thinking more ---- I have quite a few servers that do not
>> access the internet --- there are patches for the OS - Server 2000/2003,
>> IE6/7, yet I'm questioning myself ---- why patch the server OS and IE on
>> those servers if they don't access the internet. I would say definately
>> all of my LAN desktops, and just the servers that access the internet ---
>> Exchange, FTP, web server, the other servers, don't patch. All systems on
>> the LAN do have antivirus/spyware installed, my Exchange server also have
>> Mail security for SMTP installed.
>>
>> So ---- what are your feelings/what do you practice ---- just patch
>> servers that access the internet ?
>>
>> Thanks,
>> Bob
>>

> What happens if a Trojan/Worm/Virus infects a workstation
> that accesses an un-patched non-Internet accessing server?
>
> Seems that server would be vulnerable too.
>
> If you locked down each server to the bare minimum of
> services for the server task, then you could possibly install
> less patches.


And what happens if some of the individuals that might like to try to take
advantage of the vulnerabilities being patched happen to work for your
company?

/Al


 
Reply With Quote
 
Dave Warren
Guest
Posts: n/a

 
      03-13-2009
In message <eq6ul.14616$> moncho
<> was claimed to have wrote:

>Al Dunbar wrote:
>> "moncho" <> wrote in message
>> news:j0wtl.14505$...
>>> Bob wrote:
>>>> Hello all,
>>>>
>>>> For years I have been a robot and patching all systems - desktops and
>>>> servers as MS releases them. I do test them first, then install via WSUS.
>>>>
>>>> I have been thinking more ---- I have quite a few servers that do not
>>>> access the internet --- there are patches for the OS - Server 2000/2003,
>>>> IE6/7, yet I'm questioning myself ---- why patch the server OS and IE on
>>>> those servers if they don't access the internet. I would say definately
>>>> all of my LAN desktops, and just the servers that access the internet ---
>>>> Exchange, FTP, web server, the other servers, don't patch. All systems on
>>>> the LAN do have antivirus/spyware installed, my Exchange server also have
>>>> Mail security for SMTP installed.
>>>>
>>>> So ---- what are your feelings/what do you practice ---- just patch
>>>> servers that access the internet ?
>>>>
>>>> Thanks,
>>>> Bob
>>>>
>>> What happens if a Trojan/Worm/Virus infects a workstation
>>> that accesses an un-patched non-Internet accessing server?
>>>
>>> Seems that server would be vulnerable too.
>>>
>>> If you locked down each server to the bare minimum of
>>> services for the server task, then you could possibly install
>>> less patches.

>>
>> And what happens if some of the individuals that might like to try to take
>> advantage of the vulnerabilities being patched happen to work for your
>> company?
>>
>> /Al

>
>I'm with ya on that one. All good reasons to keep everything up-to-date
>as much as possible.
>
>If you know your employees are the ones trying to take advantage of the
>vulnerabilities and it is not their job to do so, then fire and
>prosecute.


The key words being "if you know" -- Until you know, those well
documented but unpatched vulnerabilities are like candy.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Patch causing failure to access Internet KingMe Windows Update 0 03-11-2007 07:34 PM
Patch Windows 2003 without Internet access Marcel Rüegg Windows Server 1 09-07-2006 02:03 PM
Internet access/Email problems with security patch 822831 Larry Bellan Windows Update 0 02-18-2004 06:20 AM
Can you update a server that has no internet access and no SUS without manually installing each patch? Paul Windows Update 1 10-02-2003 07:29 PM
Can't Access Server over the Internet Since Patch Mitchell A. Ogden Windows Update 2 08-22-2003 05:13 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59